7.5
CVSSv2

CVE-2019-19905

Published: 19/12/2019 Updated: 27/12/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

NetHack 3.6.x prior to 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nethack nethack

Vendor Advisories

Debian Bug report logs - #947005 nethack: CVE-2019-19905: buffer overflow when parsing config files Package: src:nethack; Maintainer for src:nethack is Debian Games Team <pkg-games-devel@listsaliothdebianorg>; Reported by: Reiner Herrmann <reiner@reiner-hde> Date: Thu, 19 Dec 2019 11:00:02 UTC Severity: grave Tag ...